Almost nine out of ten German companies were targeted by cyberattacks in the past year. The Cyber Risk Index, published at the end of April, identifies business-critical data from areas such as finance, research and development, publicly accessible corporate communications, and confidential information as some of the most frequently targeted assets in professional cyberattacks. Seven out of ten respondents expect one or more cyberattacks targeting their intellectual property within the next twelve months. According to the Cyber Risk Index, companies should therefore take immediate action, improve their detection capabilities, and reassess their current cybersecurity strategies.
Best Practices Cybersecurity
CYBERSECURITY: Five Tips for Successful Cybersecurity Management
17. May 2022
5 min. reading time

At the end of April, Trend Micro published its latest edition of “Kroker’s Look @ IT.” The figures from the semi-annual Cyber Risk Index speak for themselves: 87% of respondents in Germany stated that they had experienced one or more successful cyberattacks within the previous twelve months. Three-quarters of those surveyed in Germany reported the loss or theft of customer data. Additional consequences included significant costs resulting from fines, legal proceedings, IT infrastructure damage, and reputational harm.
The top five cyber threats worldwide included:
- Ransomware attacks
- Phishing and social engineering
- Denial-of-service attacks
- Botnets
- Man-in-the-middle attacks
German companies are particularly concerned about targeted attacks—whether state-sponsored or carried out by highly professional international criminal groups. According to Bitkom e.V., theft, espionage, and sabotage cause annual damages of €223 billion to the German economy. This is already twice the damage level recorded in 2018/2019, with the trend continuing to rise.
According to the Cyber Risk Index, more than seven out of ten respondents expect the loss of sensitive data within the next twelve months. At the same time, European IT managers rate their organizations’ cybersecurity maturity at only 4.99 out of 10, indicating that many companies feel insufficiently prepared for coordinated cyberattacks.
It is therefore time to take action. Here are five practical tips for successful cybersecurity management:
1. Understand IT Security Management as a Continuous Improvement Process
Individual vulnerabilities or isolated attacks do not necessarily represent a serious security threat. However, the situation becomes critical when large-scale structural vulnerabilities are exploited, system response capabilities are compromised, or coordinated cyberattacks target multiple software components simultaneously. A security incident of this scale can only be effectively managed through continuous IT security management.
Organizations in the municipal, energy, and water sectors should therefore view cybersecurity as an ongoing improvement process. Developing comprehensive cybersecurity strategies and regularly challenging existing IT crisis management processes—potentially with the support of external advisors and expert partners—can significantly strengthen resilience.
2. Security-Focused Supplier Management Prevents Costly Software Supply Chain Attacks
An IT security system is only as strong as its weakest link in the supply chain. Since attackers increasingly target IT service providers, technology partners, consulting firms, and software vendors, effective and security-oriented supplier management is essential to improve protection, transparency, and operational efficiency. Every valuable asset should therefore be carefully documented, provisioned, maintained, updated, and—when necessary—decommissioned throughout its entire lifecycle.

3. IT Security Must Become a Management Responsibility
Too often, cybersecurity management is still treated as a specialized topic handled only by technically interested employees within the IT department. However, developing a unified IT, cybersecurity, and information security strategy must be firmly anchored at the executive level.
This ensures a holistic perspective and systematically involves all responsible stakeholders across the organization—from successful implementation to regular monitoring of security measures.
At the same time, employees must be made aware of security risks and encouraged to avoid careless behavior while supporting professional release, patch, and access management processes at all levels.
Many organizations still make it unnecessarily easy for attackers—for example, through weak passwords, insufficient separation between business and technical systems, or the mixing of private and professional email accounts.
4. Establish a Crisis-Resilient Business Continuity Management Strategy
Strong preventive measures—such as firewalls and antivirus solutions—are important but not sufficient. Effective Business Continuity Management (BCM) enables organizations to respond appropriately after a cyberattack has occurred and restore normal operations as quickly as possible following a disruption.
This helps minimize damage and prevents existential threats, such as those caused by interrupted supply chains or prolonged operational downtime.
5. Involve External Expertise When Needed
What if smaller organizations cannot afford comprehensive cybersecurity management internally? Similar to data protection responsibilities, it can be beneficial to appoint an external IT Information Security Officer (ISB) with clearly defined responsibilities.
Working with external specialists can also reduce internal staffing requirements, acquisition costs, and administrative effort. Experienced security partners provide independent assessments and gap analyses to identify, evaluate, and address differences between the current security status and the desired target state.
Gain an overview of possible approaches to strengthen your organization’s IT security.
Contact: security-experts@oediv.de
Newsletter
Stay Informed
Subscribe to our newsletter to receive regular insights into Identity & Access Management.
By subscribing, you agree to our Privacy Policy.
Read More
Related Articles

Compliance 2 Min. Lesezeit
CYBERSECURITY: IAM Assessments for Enhanced Security
The NIS2 Directive (Network and Information Security) is an EU-wide regulation designed to improve the cybersecurity of organizations.…
read more →
Cybersecurity 4 Min. Lesezeit
CYBERSECURITY: Case Management and Automation with a Security Orchestration, Automation and Response (SOAR) Platform
A Security Operations Center (SOC) forms the foundation of an organization's cybersecurity operations. By integrating a Security Orchestration,…
read more →
Best Practices 11 Min. Lesezeit
Identity Lifecycle Management: Why the Lifecycle of an Identity Never Ends with Onboarding
A digital lifecycle never ends with onboarding, which is why a comprehensive identity and access strategy forms the…
read more →Ready for an Initial Consultation?
Let's assess together how resilient and future-ready your Identity & Access Management strategy really is.